Jamie Magee
@jamiemagee.bsky.social
Programmer, Engineer, Problem Solver. Maintainer of Dependabot. Principal software engineer at Microsoft/GitHub.
I drew a police sketch of Jimothy in case the cops need it
npm 12 is hot off the presses!
npm v12 is now generally available. npm install now makes install scripts, Git, and remote-URL dependencies opt-in by default. We're also retiring npm 2FA-bypass GAT: no account management (early Aug 2026), no direct publishing (~Jan 2027). More info at github.blog/changelog/20...
The World Cup has shown that Seattle with 1 million people would be awesome
Nation Turns 250 Despite Presence Of Irish https://theonion.com/nation-turns-250-despite-presence-of-irish/
#rstats Automating PKGBUILDS for AUR for most of the new R tooling out there using the tutorial jamiemagee.co.uk/blog/maintai... by @jamiemagee.bsky.social github.com/novica/aur-p...
GitHub - novica/aur-packages: PKGBUILDs for Arch Linux
PKGBUILDs for Arch Linux . Contribute to novica/aur-packages development by creating an account on GitHub.
github.com
A long overdue change in npm 12: install scripts off by default. github.blog/changelog/20...
Upcoming breaking changes for npm v12 - GitHub Changelog
Our next npm major version, v12, introduces security-related default changes to npm install. All these changes are available behind warnings in npm today on 11.16.0 or newer, so you can…
github.blog
Npm will block all auto-running installation scripts starting next month with the release of version 12.0. The change is meant to counter the rising number of supply-chain attacks taking place on the platform github.blog/changelog/20...
Upcoming breaking changes for npm v12 - GitHub Changelog
Our next npm major version, v12, introduces security-related default changes to npm install. All these changes are available behind warnings in npm today on 11.16.0 or newer, so you can…
github.blog
With Ankit Kumar Honey, senior engineering manager at GitHub, working on the Dependabot ecosystem, and Jamie Magee, principal software engineer at Microsoft, focusing on open source software and supply chain security, who contributed the Dependabot Nix support. fulltimenix.com/episodes/dep...
Turns out "let me just npm install real quick" was a security incident the whole time v12 is making dependency install scripts opt-in. I helped build it. You're welcome/I'm sorry. github.blog/changelog/20...
Upcoming breaking changes for npm v12 - GitHub Changelog
Our next npm major version, v12, introduces security-related default changes to npm install. All these changes are available behind warnings in npm today on 11.16.0 or newer, so you can…
github.blog
My OSSNA talk is now up on the Linux Foundation YouTube channel: Beyond SBOMs SBOMs tell you what's in your software. Not what you're allowed to do with it. That's the gap ClearlyDefined fills. If you've ever fought a NOTICE file, this one's for you: www.youtube.com/watch?v=gUF1...
Beyond SBOMs: Making License Data Actionable With ClearlyDefined - Jamie Magee, Microsoft
YouTube video by The Linux Foundation
youtube.com
Seattle's light rail & streetcar lines carried 4.8 million riders in April—a 44% increase above March, after Link Line 2 was extended to connect Seattle & Bellevue across Lake Washington. Seattle's light rail & streetcar lines are now the most-ridden in the nation, above LA, Boston, or San Diego.
🚀 Wow, this is finally happening! npm plans to block postinstall scripts by default in a future release In the near future (phased rollout), we will likely get a warning github.com/npm/cli/pull...
Npm registry sets stage for more secure package publishing
Npm registry sets stage for more secure package publishing
All the world's a stage, and all the packages are merely players
theregister.com
shipped three new build warnings so your dotnet SDK can finally tell on itself. you're welcome jamiemagee.co.uk/blog/a-new-w...
A new way to catch a vulnerable .NET SDK
When NuGet finds a vulnerable package in your project, it tells you. NU1901 through NU1904 have warned about CVEs in your dependencies for a while now. The SDK that runs the build, though? That’s been...
jamiemagee.co.uk
npm staged publishing has shipped 🎉 Your CI can now stage a publish without 2FA, but a human still has to approve it with a hardware key before anything goes live on the registry. Stolen npm tokens stop being game over. Big deal for the Shai-Hulud class of worm. docs.npmjs.com/staged-publi...
Staged publishing for npm packages | npm Docs
Documentation for the npm registry, website, and command-line interface
docs.npmjs.com
Heads up maintainers of packages, this is a big deal: github.com/orgs/communi...
npm granular access token invalidation to prevent supply chain attacks · community · Discussion #196340
As initially announced on npm’s X channel, we have invalidated granular access tokens with write access that bypass two-factor authentication. This action was taken to help prevent supply chain att...
github.com
I'll be speaking at the Open Source Summit on Tuesday at 11:55 about how Clearly Defined can enhance your SBOMs and make license data actionable. I'll also be at the Microsoft booth on Monday morning. See you there! osselcna2026.sched.com/event/2JQvf/...
Open Source Summit + Embedded Linux Conference North America 2026: Beyond SBOMs: Making License Data Action...
View more about this event at Open Source Summit + Embedded Linux Conference North America 2026
osselcna2026.sched.com
Just opened an npm RFC to make dependency install scripts opt-in by default. The thing about install scripts: they run the moment a package lands in your dep tree. No require, no review. That's why Shai-Hulud, chalk/debug, and Axios all used them. github.com/npm/rfcs/pul...
[RFC] Make install scripts opt-in by JamieMagee · Pull Request #868 · npm/rfcs
Summary Block dependency install scripts (preinstall, install, postinstall, and auto-detected node-gyp builds) by default during npm install. Projects opt in to running scripts for specific depende...
github.com
Debian Release Team: Debian Must Now Ship Reproducible Packages - https://www.phoronix.com/news/Debian-Must-Ship-Reproducible
Debian Release Team: Debian Must Now Ship Reproducible Packages
With half-way through the Debian 14 "Forky" development cycle, the Debian release team is out with an update this weekend and some big news...
phoronix.com
From LLMs to the supply chain to hardware and beyond, Nix is the right tool—and paradigm—for our time. In our new post, CEO @grahamc.com lays out why he thinks the Nix moment is upon us and how DetSys is leading the way. determinate.systems/blog/the-nix...
The Nix moment
The stars are aligning in unmistakable ways for Nix and we are leading the charge.
determinate.systems
2.0.0 is released 🎉 github.com/package-url/...
Release 2.0.0 · package-url/packageurl-dotnet
This is a big one. Basically a rewrite of the internals to properly follow ECMA-427, with breaking changes we'd been putting off. Breaking Nullable reference types are on (#73). Namespace, Version...
github.com
The package url spec (the `pkg:` scheme used in SBOMs and CVEs) became a formal ECMA standard in December (ECMA-427). I maintain the .NET implementation and just put out a 2.0 release candidate with full spec conformance. Stable release coming soon. github.com/package-url/packageurl-dotnet
Ubuntu 26.04 LTS officially released!!! Download ubuntu.com/download/des... Release info documentation.ubuntu.com/release-note...
Download Ubuntu Desktop | Ubuntu
Ubuntu is an open source software operating system that runs from the desktop, to the cloud, to all your internet connected things.
ubuntu.com
TypeScript 7.0 Beta is here! Built on a new native and parallelized foundation, it's already being used on multi-million line codebases. Read up more here and try it on your projects today! devblogs.microsoft.com/typescript/a...
Announcing TypeScript 7.0 Beta - TypeScript
Today we are absolutely thrilled to announce the release of TypeScript 7.0 Beta! If you haven’t been following TypeScript 7.0’s development, this release is significant in that it is built on a comple...
devblogs.microsoft.com
I built Nix flake support for Dependabot and it shipped today 🚀 Just add package-ecosystem: "nix" to your dependabot.yml and it'll open PRs for each outdated flake input. github.blog/changelog/2026-04-07-dependabot-version-updates-now-support-the-nix-ecosystem/
Dependabot version updates now support the Nix ecosystem - GitHub Changelog
Dependabot now supports Nix flakes. Add nix as a package ecosystem in your dependabot.yml file. Dependabot will then monitor your flake.lock inputs and open pull requests when newer commits are…
github.blog
Reminds me of this classic shinesolutions.com/2018/01/08/f...
Shine Solutions - Falsehoods Programmers Believe About Names
40 common false assumptions programmers make about names, debunked with real-world examples from global naming systems and identity practices.
shinesolutions.com
My name is Séamas O'Reilly. Most of the time. www.irishtimes.com/life-style/p...
TypeScript 6.0 is now available! This release brings better type-checking for methods, new standard library features, new module features for Node.js, and more! But most important, this release brings us one step closer to the upcoming native-speed 7.0! devblogs.microsoft.com/typescript/a...
Announcing TypeScript 6.0 - TypeScript
TypeScript 6.0 is now available! TypeScript 6 is a stepping-stone release, aligning with the upcoming native-speed 7.0 release.
devblogs.microsoft.com